Taiwan says it spent part of last month fending off a hacking campaign that leaned on artificial intelligence to do the heavy lifting.
The island’s Ministry of Digital Affairs, through its National Institute of Cyber Security, disclosed that government agencies were targeted in July, with alerts going out from around 20 July.
What makes the episode notable is not the break-in itself but the method. According to the ministry, the campaign blended old-fashioned manual hacking with the assistance of AI agents, software that can be pointed at a target and left to reason and act largely on its own. One such agent, “Open Claw”, was cited as an example of the agent-assisted approach.
The result was speed. Over roughly four days the attackers extracted “scores of passwords”, stole personnel records from the justice ministry, and probed a nuclear-safety agency for vulnerabilities.
That kind of breadth once demanded a skilled human team working for weeks, which is partly why the question of who is liable when a rogue AI agent hacks a company has stopped being hypothetical.
The targets were government bodies, and the reported activity ranged from credential theft to broader data extraction. The ministry said the affected units had “successively completed their handling”, and insisted that “the relevant attack sources, methods, and scope of impact have all been fully investigated”.
Officials described the source as overseas but stopped short of naming a culprit, and no threat-actor group has been identified.
The disclosure nonetheless lands amid the persistent tensions between Taiwan and China, and it is not hard to read a subtext into the timing, even if the evidence made public does not spell one out.
The wider context arrived from outside Taiwan. The disclosure follows a report by the cybersecurity firm Dream describing an AI-driven campaign against an unnamed Asian government, later identified as Taiwan by the Financial Times.
That is roughly the sequence in which these stories now tend to surface: a private firm spots the pattern, and the government confirms it afterwards.
For all the talk of autonomous machines, the humans have not left the building. “There’s still a human in there somewhere,” one security researcher cautioned of the campaign. “It’s not totally 100% autonomous.”
The distinction matters, because the AI here is an accelerant rather than a replacement, and accelerants are the sort of thing defenders lose sleep over.
What that acceleration lowers is the barrier to entry. An AI agent recently faked identities to plant malware, and the tools involved are cheap, widely available, and improving fast, which quietly hands the resources of a state to almost anyone willing to run them.
The vulnerabilities cut both ways, mind. Researchers have shown that these agents can be turned against their own operators, in one case tricking an OpenClaw agent into leaking AWS keys and customer data with nothing more than a phishing email. An attacker’s clever assistant is also a fresh attack surface.
Taiwan is, in many respects, the obvious place to watch this play out first. It sits at the sharp end of geopolitical pressure, runs a dense and heavily digitised public sector, and has long served as a proving ground for cyber-techniques that later surface elsewhere.
The compression of time is the part worth dwelling on. What used to be measured in the weeks a human crew needed to move laterally through a network can now, on this evidence, be squeezed into a long weekend, which rewrites the arithmetic for everyone tasked with defending one.
Taiwan says it has since tightened monitoring and issued protective guidance across its agencies. Whether that proves enough is another matter, because if a handful of AI agents can rifle through government systems in four days, the next campaign is unlikely to wait politely for the defenders to catch up.
Get the TNW newsletter
Get the most important tech news in your inbox each week.